Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: A company's risk assessment identifies a high…

A company's risk assessment identifies a high likelihood of a data breach due to outdated encryption standards. The cost to upgrade encryption is $50,000, and the estimated loss from a breach is $2,000,000. The risk manager decides to implement the upgrade. Which risk treatment option is being applied?

⚠ Common exam trap

It's easy for candidates to confuse risk mitigation with risk avoidance, as candidates may think avoiding outdated encryption means avoiding the risk entirely, but risk avoidance requires ceasing the risky activity, not upgrading the control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Risk mitigation

The risk manager is applying risk mitigation by implementing the encryption upgrade to reduce the likelihood or impact of a data breach. This directly addresses the identified risk by deploying a stronger cryptographic control, such as moving from AES-128 to AES-256 or replacing deprecated TLS 1.0/1.1 with TLS 1.3, thereby lowering the residual risk to an acceptable level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Risk acceptance

    Why it's wrong here

    Risk acceptance is a deliberate decision by an organization to take no action to reduce the likelihood or impact of a specific risk, often because the cost of mitigation outweighs the potential harm or the risk falls within the organization's established risk appetite. In this scenario, upgrading encryption represents a proactive control implementation, which is a direct action to reduce risk, thereby contradicting the principle of accepting the risk without further intervention.

  • Risk avoidance

    Why it's wrong here

    Risk avoidance involves eliminating the activity or asset that gives rise to the risk entirely, thereby removing the possibility of the risk event occurring. If the identified risk is associated with the use of encryption, true avoidance would necessitate discontinuing the use of encryption altogether. Upgrading the encryption, however, signifies a continued engagement with the technology, merely enhancing its security rather than abandoning it.

  • Risk enhancement

    Why it's wrong here

    "Risk enhancement" is not a recognized or standard risk treatment strategy within established cybersecurity frameworks such as ISO 27005 or NIST SP 800-30. Standard risk treatment options focus on reducing, transferring, avoiding, or accepting risks. This term might be confused with concepts like 'opportunity enhancement' in project management, but it does not apply to the management of negative risks in information security.

  • Risk transfer

    Why it's wrong here

    Risk transfer involves shifting the financial burden or responsibility associated with a risk to a third party, typically through mechanisms like purchasing cybersecurity insurance, outsourcing a risky function, or contractual agreements. Upgrading internal encryption systems is an internal control measure designed to reduce the organization's direct exposure to the risk. It does not involve shifting the risk's financial impact or operational responsibility to an external entity.

  • Risk mitigation

    Why this is correct

    Risk mitigation involves implementing controls or countermeasures to reduce the likelihood or impact of a risk event to an acceptable level. Upgrading to stronger encryption algorithms, increasing key lengths, or improving cryptographic protocols directly reduces the probability of a successful attack against encrypted data. This action directly lessens the organization's exposure to a data breach, aligning precisely with the definition and objective of risk mitigation.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

Go deeper

Related to this question

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.